Jan 022014
 

When you obtain a NetLM password hash with the known challenge of 1122334455667788 you are able to utilize the HALFLMCHALL rainbowtable to identify the first seven (7) characters of the password. The second half is left to identify. Tutorials exist (including my site, as well as here and here) on how to capture the NetLM hash using Metasploit. Metasploit comes with a Ruby script in the tools folder that will bruteforce the remaining characters of the password when you provide the complete NetLM hash and the first seven (7) characters of the recovered password. However, for passwords that are 11+ characters it is time prohibitive to bruteforce the remaining characters as show below.
Continue reading »

Jan 012014
 

Download the Rcracki_mt Linux binary from http://sourceforge.net/projects/rcracki/files/rcracki_mt/rcracki_mt_0.7.0/

$ sudo apt-get install p7zip links
$ cd ~/tools
~/tools$ links http://sourceforge.net/projects/rcracki/files/rcracki_mt/rcracki_mt_0.7.0/rcracki_mt_0.7.0_linux_x86_64.7z/download
~/tools$ p7zip -d rcracki_mt_0.7.0_linux_x86_64.7z
~/tools$ cd rcracki_mt_0.7.0_linux_x86_64/

Download the HALFLMCHALL Rainbowtables from https://www.freerainbowtables.com/tables/

$ mkdir -p RainbowTables/halflmchall
$ cd RainbowTables/halflmchall
~/RainbowTables/halflmchall$ wget http://freerainbowtables.mirror.garr.it/mirrors/freerainbowtables/halflmchall/halflmchall_alpha-numeric%231-7_0/halflmchall_alpha-numeric%231-7_0_2400x57648865_1122334455667788_distrrtgen%5bp%5d%5bi%5d_0.rti
~/RainbowTables/halflmchall$ wget http://freerainbowtables.mirror.garr.it/mirrors/freerainbowtables/halflmchall/halflmchall_alpha-numeric%231-7_0/halflmchall_alpha-numeric%231-7_0_2400x57648865_1122334455667788_distrrtgen%5bp%5d%5bi%5d_0.rti.index
~/RainbowTables/halflmchall$ wget http://freerainbowtables.mirror.garr.it/mirrors/freerainbowtables/halflmchall/halflmchall_alpha-numeric%231-7_1/halflmchall_alpha-numeric%231-7_1_2400x56281894_1122334455667788_distrrtgen%5bp%5d%5bi%5d_0.rti
~/RainbowTables/halflmchall$ wget http://freerainbowtables.mirror.garr.it/mirrors/freerainbowtables/halflmchall/halflmchall_alpha-numeric%231-7_1/halflmchall_alpha-numeric%231-7_1_2400x56281894_1122334455667788_distrrtgen%5bp%5d%5bi%5d_0.rti.index
~/RainbowTables/halflmchall$ wget http://freerainbowtables.mirror.garr.it/mirrors/freerainbowtables/halflmchall/halflmchall_alpha-numeric%231-7_2/halflmchall_alpha-numeric%231-7_2_2400x58928524_1122334455667788_distrrtgen%5bp%5d%5bi%5d_0.rti
~/RainbowTables/halflmchall$ wget http://freerainbowtables.mirror.garr.it/mirrors/freerainbowtables/halflmchall/halflmchall_alpha-numeric%231-7_2/halflmchall_alpha-numeric%231-7_2_2400x58928524_1122334455667788_distrrtgen%5bp%5d%5bi%5d_0.rti.index
~/RainbowTables/halflmchall$ wget http://freerainbowtables.mirror.garr.it/mirrors/freerainbowtables/halflmchall/halflmchall_alpha-numeric%231-7_3/halflmchall_alpha-numeric%231-7_3_2400x58924114_1122334455667788_distrrtgen%5bp%5d%5bi%5d_0.rti
~/RainbowTables/halflmchall$ wget http://freerainbowtables.mirror.garr.it/mirrors/freerainbowtables/halflmchall/halflmchall_alpha-numeric%231-7_3/halflmchall_alpha-numeric%231-7_3_2400x58924114_1122334455667788_distrrtgen%5bp%5d%5bi%5d_0.rti.index